Deployment Architecture

how to know and delete old indexed log files in hard disk?

shariinPH
Contributor

Hi all
I want to know what are the old indexed log file and at the same time delete those log files on my hard disk
Pls help me with this.

Thanks

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi shariinPH,

If you haven't set any coldToFrozenScript in your indexes.conf your old events will not be archived http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Automatearchiving

That said, if you're using all default settings for your indexes, Splunk will delete any old events for you.
Check the docs for more details on that http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Setaretirementandarchivingpolicy

Hope that helps ...

cheers, MuS

shariinPH
Contributor

Thanks @MuS !!:)

0 Karma

MuS
SplunkTrust
SplunkTrust

If this answers your question, please accept it - thx 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...